Which of the following post-exploitation activities allows a penetration tester to maintain persistent access in a compromised system?
Maintaining persistent access in a compromised system is a crucial goal for a penetration tester after achieving initial access. Here's an explanation of each option and why creating registry keys is the preferred method:
Creating registry keys (Answer: A):
Advantages: This method is stealthy and can be effective in maintaining access over long periods, especially on Windows systems.
Example: Adding a new entry to the HKLMSoftwareMicrosoftWindowsCurrentVersionRun registry key to execute a malicious script upon system boot.
Drawbacks: This method is less stealthy and can be easily detected by network monitoring tools. It also requires an open port, which might be closed or filtered by firewalls.
Executing a process injection (Option C):
Drawbacks: While effective for evading detection, it doesn't inherently provide persistence. The injected code will typically be lost when the process terminates or the system reboots.
Setting up a reverse SSH connection (Option D):
Drawbacks: This method can be useful for maintaining a session but is less reliable for long-term persistence. It can be disrupted by network changes or monitoring tools.
Conclusion: Creating registry keys is the most effective method for maintaining persistent access in a compromised system, particularly in Windows environments, due to its stealthiness and reliability.
Installing a bind shell (Option B):
Hannah
3 months agoJuan
3 months agoIvette
2 months agoVeronika
2 months agoIra
2 months agoCarrol
3 months agoStaci
3 months agoViva
3 months agoNicolette
3 months agoBuffy
3 months agoSoledad
3 months agoPhuong
3 months agoDorothy
3 months agoLucina
4 months agoTula
3 months agoLilli
3 months agoGregoria
3 months agoTien
4 months agoLayla
2 months agoFrancine
3 months agoLeontine
3 months agoDean
3 months agoJudy
4 months agoArlyne
3 months agoStefania
3 months agoStefania
3 months agoMagnolia
4 months agoJosephine
4 months agoMertie
4 months agoKenneth
4 months agoEdmond
4 months agoKing
4 months agoLavina
4 months ago